First published: Fri Dec 31 2004(Updated: )
webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare | =6.5-sp1 | |
Novell NetWare | =6.5-sp1.1a | |
Novell NetWare | =6.5-sp1.1b | |
Novell NetWare | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2734 has a high severity rating due to the potential for unauthorized access to protected directories.
To fix CVE-2004-2734, you should correct the alias tag configuration in webadmin-apache.conf to ensure consistent casing.
CVE-2004-2734 affects Novell NetWare 6.5, including service packs 1, 1a, and 1b.
CVE-2004-2734 can be exploited by remote attackers to gain unauthorized access to the WEB-INF folder.
CVE-2004-2734 was published on December 23, 2004.